Anomaly detection of internet of medical things cyberattacks using federated learning
Abstract Devices connected to the Internet of Medical Things (IoMT) handle sensitive patient data under strict privacy and resource constraints. Centralized intrusion detection introduces privacy risks and communication bottlenecks, while existing Federated Learning (FL) solutions struggle with class imbalance and data heterogeneity. This paper proposes One-Shot Federated Anomaly Detection (OneShot-FedAD), which completes feature selection and model training in a single communication round, eliminating iterative weight exchange. It integrates Federated Differential Privacy Mutual Information (DP-MI) for feature selection, local Synthetic Minority Oversampling Technique (SMOTE) to reduce false alarms without sharing raw data, and Adaptive Weighted Aggregation (AWA) based on each client’s local validation F1-score. Across seven experiments on CICIoMT2024 and WUSTL-EHMS-2020, LightGBM achieves 99.75% accuracy and 99.87% F1-score on CICIoMT2024, stable across five random seeds (99.88% ± 0.01%, 95% CI), and 93.77% accuracy with 55.70% attack recall on WUSTL-EHMS-2020, reflecting severe class imbalance on this smaller dataset. DP-MI reduces the feature space by 28.57–44.44%. With per-client uploads under 350 KB, a 1.7 MB aggregated model, and 9.01–24.14 µs inference latency (72–193 µs under an 8 $$\times $$ hardware slowdown), OneShot-FedAD is feasible on 512 MB edge devices.
Authors
- Ahmed Aljughaiman (ORCID: https://orcid.org/0000-0001-9176-9453)
- Sarah Alfayz
- Maha AlMarri
Institutions
- King Faisal University (SA)
Publication Details
- Journal
- Scientific Reports
- Published
- 2026-09-30
- DOI
- https://doi.org/10.1038/s41598-026-69924-2
- Primary Topic
- Anomaly Detection Techniques and Applications
- Type
- article
- Field-Weighted Citation Impact
- 0.00